Server
by Devolutions
CVEs (114)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-10787 | Med | 0.28 | 4.3 | 0.00 | Jun 8, 2026 | Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server… | ||
| CVE-2026-9246 | Med | 0.28 | 4.3 | 0.00 | May 22, 2026 | Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a crafted API request. This issue affects : * Devolutions… | ||
| CVE-2026-9224 | Med | 0.28 | 4.3 | 0.00 | May 22, 2026 | Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attributes via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * … | ||
| CVE-2026-9223 | Med | 0.28 | 4.3 | 0.00 | May 22, 2026 | Missing authorization in the vault import feature in Devolutions Server 2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request. | ||
| CVE-2026-5171 | Med | 0.28 | 4.3 | 0.00 | May 22, 2026 | Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request. This issue affects : * Devolutions… | ||
| CVE-2026-5146 | Med | 0.28 | 4.3 | 0.00 | May 12, 2026 | Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation. This issue affects the following versions : * Devolutions… | ||
| CVE-2026-8407 | Med | 0.28 | 4.3 | 0.00 | May 12, 2026 | Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted requests to PAM API endpoints. This issue affects the following versions : *… | ||
| CVE-2026-4989 | Med | 0.28 | 4.3 | 0.00 | Apr 1, 2026 | Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticated user to perform server-side request forgery (SSRF), potentially leading to information disclosure, via a crafted API request. This issue affects Server: from… | ||
| CVE-2026-1768 | Med | 0.28 | 4.3 | 0.00 | Feb 24, 2026 | A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.This issue affects Devolutions Server: before 2025.3.15. | ||
| CVE-2025-13765 | Med | 0.28 | 4.3 | 0.00 | Nov 27, 2025 | Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9. | ||
| CVE-2025-4316 | Med | 0.28 | 4.3 | 0.00 | May 5, 2025 | Improper access control in PAM feature in Devolutions Server allows a PAM user to self approve their PAM requests even if disallowed by the configured policy via specific user interface actions. This issue affects Devolutions Server versions from 2025.1.3.0 through… | ||
| CVE-2024-12148 | Med | 0.28 | 4.3 | 0.00 | Dec 4, 2024 | Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints. | ||
| CVE-2024-10971 | Med | 0.28 | 4.3 | 0.01 | Nov 12, 2024 | Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission. | ||
| CVE-2024-3545 | Med | 0.28 | 4.3 | 0.00 | Apr 9, 2024 | Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining… | ||
| CVE-2024-1901 | Med | 0.28 | 4.3 | 0.00 | Mar 5, 2024 | Denial of service in PAM password rotation during the check-in process in Devolutions Server 2023.3.14.0 allows an authenticated user with specific PAM permissions to make PAM credentials unavailable. | ||
| CVE-2024-1898 | Med | 0.28 | 4.3 | 0.00 | Mar 5, 2024 | Improper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privileged user to change notifications settings configured by an administrator. | ||
| CVE-2025-11958 | Med | 0.27 | 4.1 | 0.00 | Oct 22, 2025 | An improper input validation in the Security Dashboard ignored-tasks API of Devolutions Server 2025.2.15.0 and earlier allows an authenticated user to cause a denial of service to the Security Dashboard via a crafted request. | ||
| CVE-2025-13758 | Low | 0.23 | 3.5 | 0.00 | Nov 27, 2025 | Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8. | ||
| CVE-2024-2918 | Low | 0.23 | 3.6 | 0.00 | Apr 9, 2024 | Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to forge the displayed group in the PAM JIT elevation checkout request via a specially crafted request. | ||
| CVE-2026-9249 | Low | 0.20 | 3.1 | 0.00 | May 22, 2026 | Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server… |
- risk 0.28cvss 4.3epss 0.00
Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server…
- risk 0.28cvss 4.3epss 0.00
Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documentation and attachments of sealed entries via a crafted API request. This issue affects : * Devolutions…
- risk 0.28cvss 4.3epss 0.00
Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attributes via a crafted API request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * …
- risk 0.28cvss 4.3epss 0.00
Missing authorization in the vault import feature in Devolutions Server 2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.
- risk 0.28cvss 4.3epss 0.00
Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but without the required permission to retrieve that entry's activity logs via a crafted API request. This issue affects : * Devolutions…
- risk 0.28cvss 4.3epss 0.00
Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session validation. This issue affects the following versions : * Devolutions…
- risk 0.28cvss 4.3epss 0.00
Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted requests to PAM API endpoints. This issue affects the following versions : *…
- risk 0.28cvss 4.3epss 0.00
Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticated user to perform server-side request forgery (SSRF), potentially leading to information disclosure, via a crafted API request. This issue affects Server: from…
- risk 0.28cvss 4.3epss 0.00
A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.This issue affects Devolutions Server: before 2025.3.15.
- risk 0.28cvss 4.3epss 0.00
Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.
- risk 0.28cvss 4.3epss 0.00
Improper access control in PAM feature in Devolutions Server allows a PAM user to self approve their PAM requests even if disallowed by the configured policy via specific user interface actions. This issue affects Devolutions Server versions from 2025.1.3.0 through…
- risk 0.28cvss 4.3epss 0.00
Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints.
- risk 0.28cvss 4.3epss 0.01
Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission.
- risk 0.28cvss 4.3epss 0.00
Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining…
- risk 0.28cvss 4.3epss 0.00
Denial of service in PAM password rotation during the check-in process in Devolutions Server 2023.3.14.0 allows an authenticated user with specific PAM permissions to make PAM credentials unavailable.
- risk 0.28cvss 4.3epss 0.00
Improper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privileged user to change notifications settings configured by an administrator.
- risk 0.27cvss 4.1epss 0.00
An improper input validation in the Security Dashboard ignored-tasks API of Devolutions Server 2025.2.15.0 and earlier allows an authenticated user to cause a denial of service to the Security Dashboard via a crafted request.
- risk 0.23cvss 3.5epss 0.00
Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.
- risk 0.23cvss 3.6epss 0.00
Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to forge the displayed group in the PAM JIT elevation checkout request via a specially crafted request.
- risk 0.20cvss 3.1epss 0.00
Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server…
Page 5 of 6